Information Security Specialist - 3rd Party Vendor Risk Management
Remote job
Riverflex
Job Title: Information Security Vendor (3rd Party) Risk Management Subject Matter Expert (SME)
Location: Remote
Position Type: Full-Time/ Part Time
About Us:
Our client, a prominent player in the global shipping industry, has a steadfast commitment to cybersecurity excellence. They understand the vital role third-party vendors play in their operations and the significance of effectively managing associated security risks.
In line with their dedication to safeguarding digital assets and ensuring business continuity, our client is seeking an experienced Information Security Vendor (3rd Party) Risk Management SME. This role underscores their commitment to fortify security measures and resilience in partnership with third-party collaborators.
Key Responsibilities:
As an Information Security Vendor (3rd Party) Risk Management SME, you will:
- Risk Assessment and Prioritization: Utilize a variety of 3rd party risk management frameworks and best practices to prioritize, assess, and mitigate security risks associated with our extensive network of third-party vendors (approximately 50,000 globally). Recommend pragmatic and efficient methods to manage these risks effectively.
- Vendor Risk Expertise: Leverage your extensive experience and focus on third-party (vendor) risk management to ensure that our organization remains resilient and secure in a complex global environment.
- Innovative Risk Assessment: Identify innovative and modern techniques for efficiently assessing and segmenting 3rd party security risks, enabling us to make informed decisions and allocate resources effectively.
- Industry Insights: Bring your 3rd party risk management experience and insights from similar mid-sized, multi-country organizations to enhance our risk management strategies.
- Process and Policy Enhancement: Collaborate with stakeholders to define and recommend new processes and policies that streamline and optimize third-party security risk management practices. Emphasize simplicity, efficiency, and intuitiveness in all processes.
- Risk Reporting: Design and structure suitable risk management information (MI) and risk dashboards that provide intuitive, efficient, and easy-to-adopt insights into third-party security risks.
- Documentation and Communication: Maintain thorough documentation of 3rd party security risk assessments, findings, and recommendations. Present these findings in clear, actionable reports to drive informed decisions and remediation efforts.
- Tool Development: Place a strong emphasis on defining simple, efficient, and intuitive risk management tools that align with our commitment to excellence in cybersecurity.
Requirements
Qualifications:
To excel in this role, you should possess the following qualifications and attributes:
- Strong foundation in cybersecurity principles, technologies, and tools.
- Familiarity with industry-standard security frameworks, such as NIST, ISO 27001, and CIS Critical Security Controls.
- Up-to-date knowledge of the latest cybersecurity threats and trends.
- Experience in the global shipping industry is preferable but not essential.
- Proven expertise with a demonstrated career focus on 3rd party (vendor) risk management.
- Extensive experience with 3rd party risk management frameworks and best practices.
- Innovative mindset to efficiently assess and segment 3rd party security risks in large organizations.
- Previous experience in similar roles within mid-sized, multi-country organizations.
- Track record of defining and recommending new processes and policies for efficient 3rd party security risk management.
- Proficiency in designing intuitive risk management information (MI) and risk dashboards.
- Strong documentation and communication skills, with an ability to present complex information clearly and concisely.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: ISO 27001 NIST Risk assessment Risk management
Perks/benefits: Career development
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open SOC Analyst jobs
- Open Senior Cybersecurity Engineer jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open IT Security Analyst jobs
- Open Information Security Officer jobs
- Open Senior Information Security Engineer jobs
- Open Consultant SOC / CERT H/F jobs
- Open Cyber Security Specialist jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Security Operations Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Senior SOC Analyst jobs
- Open Product Security Engineer jobs
- Open Staff Security Engineer jobs
- Open Staff Information Security Engineer jobs
- Open o365 Security Architect jobs
- Open Infosec Risk Manager jobs
- Open Cybersecurity Consultant jobs
- Open Chief Information Security Officer jobs
- Open Fortinet Firewall Engineer jobs
- Open Cyber Security Architect jobs
- Open Ingénieur DevSecops H/F jobs
- Open Application security-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open SaaS-related jobs
- Open Governance-related jobs
- Open Pentesting-related jobs
- Open Java-related jobs
- Open Analytics-related jobs
- Open ISO 27001-related jobs
- Open Clearance-related jobs
- Open Vulnerability management-related jobs
- Open CISM-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open APIs-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open Malware-related jobs
- Open Splunk-related jobs
- Open Kubernetes-related jobs
- Open CISA-related jobs
- Open DevSecOps-related jobs
- Open Terraform-related jobs
- Open IDS-related jobs
- Open GDPR-related jobs